[govsec] Morris Worm and a Change in Direction

Jack Holleran jholleran at comcast.net
Sat Nov 6 14:07:46 EST 2004


Based on the description below, this seems to be a method that might
remove copyright protections as well since a change is/has occurred and
any digital signature could not be the same.

SO possibly a protection on one hand might also be a requirement breaker
on the other hand.

Jack Holleran



  -----Original Message-----
  From: govsec-bounces at attrition.org [mailto:govsec-bounces at attrition.org]On
Behalf Of Peter Churchyard
  Sent: Saturday, November 06, 2004 10:03 AM
  To: govsec at attrition.org
  Subject: Re: [govsec] Morris Worm and a Change in Direction


    Translating content into what should be equivalent content in another
form is used. Some of the problems recently seen with image formats containg
exploits just shows that there are few safe data formats. jpeg <-> gif <->
jpeg as an example could be done at the gateway to clean up images and
remove steganography. Likewise mp3 <-> wma <-> mp3 could be used do the
same.

    what are the requirements since they will define acceptable security.



    Lori
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.attrition.org/pipermail/govsec/attachments/20041106/fe8125ee/attachment.html


More information about the govsec mailing list